Yaml
Vendor:
First CVE: Oct 16, 2025 · Active for under a year
7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Yaml over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2025
9 months ago
Most Recent CVE
Jul 16, 2026
10 days ago
CVE Severity & Scoring
Yaml7 CVEs
29%
43%
29%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (42.9%)
Network3 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57075CRITICAL YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.
The base64 decoder in the bundled libsyck indexes the | Jul 16, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-57076HIGH YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor.
In the bundled libsyck an anchor na | Jul 16, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-57077HIGH YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.
In the bundled libsyck newline_len and is_newline dereference th | Jul 16, 2026 | 7.7 | 35 | NO | NO |
CVE-2026-4177CRITICAL YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.
The heap overflow occu | Mar 16, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-13713MEDIUM YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack.
In the bundled libsyck, when an anc | Jul 16, 2026 | 6.2 | 31 | NO | NO |
CVE-2026-5089HIGH YAML::Syck versions before 1.38 for Perl has an out-of-bounds read.
The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#b | May 12, 2026 | 7.3 | 29 | NO | NO |
CVE-2025-11683MEDIUM YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure
Missing null terminators in token.c lead | Oct 16, 2025 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Yaml
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| \ | 7 | 7.7 | 0.3% | 0 | 0 |